GDPR Charter

1. Purpose of this Charter

The purpose of this Charter is to raise awareness among all employees regarding the protection of personal data and to define the essential best practices required to ensure compliance with the General Data Protection Regulation (GDPR) and applicable Data Protection Laws.

This Charter applies to all individuals working for Groupe ETMB

2. Fundamental GDPR Principles

Each employee is required to comply with the following principles:

2.1. Purpose Limitation

Personal data shall only be collected or processed for a clear, legitimate, and professional purpose.

2.2. Data Minimization

Only personal data that is strictly necessary for the intended purpose shall be collected and processed.

2.3. Accuracy

Employees must ensure that personal data remains accurate, up to date, and corrected where necessary.

2.4. Storage Limitation

Personal data shall not be retained longer than required for the purposes for which it was collected.

2.5. Security

Personal data must be protected against loss, unauthorized access, alteration, disclosure, or misuse.

2.6. Confidentiality

Personal information must never be disclosed to unauthorized persons.

3. Daily Best Practices

3.1. Document Management

  • Do not leave documents containing personal data accessible to unauthorized individuals.

  • Store paper records and archives in locked cabinets.

  • Destroy confidential documents using approved shredding equipment.

3.2. Computer Use

  • Lock your workstation whenever you leave it unattended, even for a short period.

  • Use strong and unique passwords for all professional accounts and systems.

  • Never install unauthorized software.

  • Ensure that operating systems and antivirus solutions are regularly updated.

3.3. Data Sharing and Transfers

  • Personal data may only be shared with authorized recipients.

  • Use secure communication channels and approved tools (business email, encrypted file transfer solutions, and company-approved platforms).

  • Never send sensitive data through unapproved services (such as free WeTransfer accounts, personal Gmail accounts, WhatsApp, or similar applications).

3.4. Email Management

  • Maintain a strict separation between professional and personal email accounts.

  • Use the Blind Carbon Copy (BCC) function when sending group emails containing personal data.

  • Regularly delete emails containing sensitive information once they are no longer required.

3.5. Meetings and Business Travel

  • Do not discuss personal data in public spaces.

  • Never leave documents unattended in unsecured locations such as trains, taxis, meeting rooms, or coworking spaces.

4. Sensitive Data and Restricted Access

The following categories of information require enhanced protection and vigilance:

  • Health data

  • Financial data

  • Payment card details

  • Human Resources data (salaries, employment contracts, absences)

  • Children's data

  • Identity documents

  • Access to such information is strictly limited to authorized personnel.

5. Use of Digital Tools

5.1. Internet Usage

Do not download files from untrusted sources.

Do not use personal cloud storage services (such as personal Dropbox, Google Drive, or iCloud accounts) for business purposes.

5.2. Corporate Mobile Devices

Protect company smartphones with a PIN code, biometric authentication, or equivalent security measures.

Do not store sensitive data on mobile devices without adequate protection. The use of a password manager is strongly recommended.

5.3. External Storage Devices

Only USB drives and removable media provided or approved by the Company may be used.

External storage devices should be encrypted whenever necessary.

6. Processors and Business Partners

Before sharing any personal data:

  • Verify that the processor or service provider complies with GDPR requirements.

  • Ensure that an appropriate Data Processing Agreement (DPA) is in place.

  • Share only the information that is strictly necessary.

7. Data Breaches: Required Actions

A personal data breach may include:

  • Loss of a USB device;

  • An email sent to the wrong recipient;

  • Cyberattacks or unauthorized access;

  • Accidental disclosure of information;

  • Accidental deletion of data.

Any incident must be reported immediately to the GDPR Officer at: contact@etmb.fr and to Company Management.

The Company must respond within 24 hours and, where required, notify the relevant Supervisory Authority within 72 hours.

8. Exercising Data Subject Rights

Any request from an employee, customer, supplier, or business partner concerning:

  • Access to personal data;

  • Rectification;

  • Erasure;

  • Data portability;

  • Objection to processing;

  • Restriction of processing;

Must be immediately forwarded to the Company's GDPR Representative.

No direct response should be provided to the requester without prior internal validation.

9. Employee Responsibilities

Each employee agrees to:

  • Comply with this Charter;

  • Seek guidance whenever in doubt;

  • Participate in internal training sessions;

  • Report any non-compliant behavior or practice.

10. Employee Acknowledgement

I acknowledge that I have read and understood the GDPR Best Practices Charter.
I undertake to comply with all principles and requirements set forth therein.